CVE 8.4 HIGH

AVEVA Process Optimization SQL Injection_CVE-2025-61943

8.4 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Description

The vulnerability, if exploited, could allow an authenticated miscreant
(Process Optimization Standard User) to tamper with queries in Captive
Historian and achieve code execution under SQL Server administrative
privileges, potentially resulting in complete compromise of the SQL
Server.

Basic Information

ID CVE-2025-61943
Source icscert
Published Jan 16, 2026 at 00:09

Affected Product

Vendor AVEVA
Product Process Optimization
Affected Versions AVEVA Process Optimization 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.